CVE-2026-68004
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_app_security.cpp, and SRS RTMP listener components
Published 2026-08-17. Last modified 2026-09-09.